CVE-2022-30969: CSRF
Published May 17, 2022
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins Autocomplete Parameter Plugin 1.1 and earlier allows attackers to execute arbitrary code without sandbox protection if the victim is an administrator.
Affected Software
1 affected component
jenkins Autocomplete Parameter Jenkins<=1.1
Event History
May 17, 2022
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-30969?
CVE-2022-30969 is considered a critical severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2022-30969?
To fix CVE-2022-30969, update the Jenkins Autocomplete Parameter Plugin to version 1.1 or later.
3
Is CVE-2022-30969 exploitable by non-administrators?
No, CVE-2022-30969 requires the victim to be an administrator for exploitation.
4
What impact does CVE-2022-30969 have on Jenkins installations?
CVE-2022-30969 could lead to unauthorized actions in Jenkins environments, compromising security and stability.
5
Are there any known workarounds for CVE-2022-30969?
There are currently no specific workarounds for CVE-2022-30969 aside from updating to the patched version.